TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Threat actor
Section9
ransomware3 leak-site claims, all timeLatest observed leak-site post 2026-07-30ORKL search ↗
Portable threat brief
Section9
Versioned profile fields only · no model narrative
Opens the browser print dialog; choose Save as PDF.
PDF export is unavailable. The threat brief remains available below; use your browser's Print command.
Executive facts
Actor
Section9
Kind
ransomware
Actor record created
2026-07-26
Latest observed
2026-07-30
Leak-site claims
3
Catalogued techniques
0
Scope
Tracked sectors
Energy & Utilities, Hospitality
Claim records
2026-07-26 to 2026-07-30
Decisive signals with dates
No dated decisive signals are attached to this actor's linked vulnerabilities.
Verified techniques
No verified ATT&CK mapping in this corpus.
Defensive actions
No defensive actions are attached to this profile.
Most-claimed sectorsEnergy & UtilitiesHospitality
Activity window in this corpus
This is only the tracker's observed corpus window. It is not this actor's lifetime or evidence of dormancy outside these dates.
Claim records
First observed Latest observed
Verified ATT&CK phases represented
No verified ATT&CK mapping in this corpus
Origin and motivation
Origin and motivation not attributed.
No MITRE ATT&CK group mapping exists for this actor yet. Mappings here are strict: an actor links to a MITRE group only when the group's own name, aliases, or MITRE-published description match, and MITRE has not catalogued this group. Technique and defensive action data will appear automatically if a verified mapping lands.
Claims attributed to this actor or leak site
3 in this corpus
And where does the newborn go from here? The net is vast and infinite.Unclassifiedsource ↗